Wordfence blocks an IP when the request rate exceeds the limit defined in the firewall settings. The plugin records each request and compares it to the threshold. When the count passes the limit, the IP is denied access for the period set in the block duration option.
The block applies to all traffic from that address, including front‑end pages, admin login, and API calls. The user receives a Wordfence block page with a rate‑limit message and HTTP 403 or 429 responses.